Live data from Hacker News

WARP is here

blog.cloudflare.com

71–80 of 386 posts

Re: WARP is here

#71
post #54

Earlier quoted context omitted.

Can't the same be said about any of the huge hosting companies such as OVH, Hetzner, 1&1, AWS, etc. And any VPN provider that hosts their servers and routes their traffic through unknown datacenters? I'd rather trust Cloudflare that has a great track-record (+Public Canary and are on US Privacy Shield), than any random VPN provider.

Trust with what? Warp is specifically designed to reveal your IP address. This is as anti-privacy VPN as a VPN can be. Which is absolutely not surprising coming from a US corporation.

[deleted]

Re: WARP is here

#72
Does WARP block access to websites that Cloudflare has specifically denied a platform to their other services? It only makes sense that if they refused to do business with a website because they are "an environment that revels in violating [the spirit of anti-hate law]" that they would also prevent end-users from accessing it under the same grounds, no?

Re: WARP is here

#74
post #11

The article mentions that WARP is exposing the end user's IP to websites they visit. I'd be interested in how they do that, especially with HTTPS websites where they can't MITM and inject headers. > WARP is not designed to allow you to access geo-restricted content when you’re traveling. It will not hide your IP address from the websites you visit.

Great eye! We haven't figured out how to expose them yet for sites not using Cloudflare. We do have some experience solving this problem for Spectrum [1] we're hoping to lean on. The most important thing to us is users don't expect us to keep their IP private, as that is not the intent of WARP. 1- https://blog.cloudflare.com/mmproxy-creative-way-of-preservi...

Can you have an option to do that? I imagine in some cases it might be better for people (in certain regions or roles) where their IP being hidden is a core component of "Privacy First".

Re: WARP is here

#75
post #11

The article mentions that WARP is exposing the end user's IP to websites they visit. I'd be interested in how they do that, especially with HTTPS websites where they can't MITM and inject headers. > WARP is not designed to allow you to access geo-restricted content when you’re traveling. It will not hide your IP address from the websites you visit.

The requests come from a CloudFlare address range -- my original IP isn't visible to the server. Not sure what they mean either.

It passes on your IP address if the website you're visiting is using CF. See for yourself:

https://icanhazip.com - on CF network https://ifconfig.me - not on CF network

Re: WARP is here

#76

I was openly critical of Cloudflare when they announced Warp the first time. My accusations were over-reaching, and I ultimately retracted them. But I'm still skeptical, and I still won't use Warp. Here's what still bothers me: Cloudflare is a single company with points of presence all over the world, handling traffic for websites all over the world (including some big ones), and now trying to attract consumers world…

Early on in Cloudflare’s history when we were asked who our competition was we said Facebook. The concern was that the challenges of being online would get so hard that individual websites would give up and just move to run Facebook pages. We saw our role as providing the security and performance needed to compete without making you give in to use an all-consuming platform. We haven’t said that in a long time, but I…

Thank you for taking time to share your perspective. However, I remain skeptical.

It's true that a website using Cloudflare is more independent than a Facebook page, in that in the former case, the company can take their domain to another provider. But my idea of an independent Web is a large number of websites depending on a large number of high-quality hosting providers. The latter number will inevitably be smaller, but shouldn't be single-digit. That would lead to too much potential for abuse of power.

Also, the more sites are using a single provider with its black-box algorithms and heuristics, the more potential there is for bad consequences for innocent users when those things misfire. That's what worries me about the bot-fighting feature you launched on Monday.

To respond specifically to part of what you said:

> The concern was that the challenges of being online would get so hard that individual websites would give up and just move to run Facebook pages.

I don't think I understand how Cloudflare actually helps here. I think the average bar, karaoke DJ (I love karaoke), spa, or other small business that might just use a Facebook page would be served just as well by the kind of hosting provider that gives your website a single IP address pointing to a single machine. Are DDoS attacks and bots really that big of a problem? If so, I haven't run into them in the 16 years that I was the programmer and sysadmin for a small company (admittedly, online services are that company's business). Maybe we just didn't make the right enemies? Now, maybe small web hosting providers could make it even easier to set up a new website, but Cloudflare doesn't do anything about that problem anyway. If the concern is performance, maybe we need better alternatives to WordPress and Drupal, and more local hosting providers, so the website for small businesses can be closer to their mostly-local customers without using a CDN.

Re: WARP is here

#77
post #14
post #5

It sounds like an interesting product, but I'm wary of anything put out by the arbiters of the internet.

Really? The arbiters of the internet? You don't think that's maybe a little melodramatic? Cloudflare has, time and time again demonstrated openness, transparency, and insight into their technical and ethical frameworks. I trust them a whole lot more than my isp or any random vpn provider.

> The arbiters of the internet? You don't think that's maybe a little melodramatic?

As someone who has browsed sites "powered by cloudflare" over Tor and been tossed into an infinite "are you human" loop, it certainly doesn't feel melodramatic.

They've also exercised power over websites based on moral outrage. Perhaps 99.999% of people agree with the morals behind this decision, and maybe it's even the right decision, but it's still an arbitrary decision made by Cloudflare.

They are also bound by US law, and other entities bound by US law have been forced to enable the exact same forms of record keeping that Cloudflare says they will keep turned off.

Cloudflare is not a neutral party. They don't even advertise themselves as a neutral party.

Re: WARP is here

#78
post #26

> WARP, instead, is built for the average consumer. It’s built to ensure that your data is secured while it’s in transit. So the networks between you and the applications you’re using can’t spy on you. It will help protect you from people sniffing your data while you’re at a local coffee shop. It will also help ensure that your ISP isn’t hoovering up data on your browsing patterns to sell to advertisers. Most of thos…

They also states: > Before today, there were approximately two million people on the waitlist to try WARP. That demand blew us away. It also embarrassed us. The common refrain is consumers don’t care about their security and privacy, but the attention WARP got proved to us how wrong that assumption actually is.

I feel like that misses the point though. I'd be shocked (and happily wrong) if a large portion of those 2M users are none technical average people.

If anything, all I would take from that number is that the tech crowd is perhaps larger than people give it credit for. But I highly doubt that waitlist expands highly beyond the tech crowd.

Happy to be wrong, though :)

Re: WARP is here

#79
Super excited about 1.1.1. Warp.

kudos @ launching, have been waiting for this

How I see it: a well operated VPN service for whenever you trust Cloudflare more than the internet connection you’re currently on (coffee shop or airport wifi, co-working space, random mobile ISP when traveling or even at home, …).

Compare this to the current best alternative: difficult to evaluate VPNs ranging from paid to free & non-trivial to set up.

Not saying there are no alternatives but even for me it is not easy to tell which ones are actually better or in the same ballpark (@ trust, speed, ops-skills, …) let alone for the longtail of users who would be better off with something like Cloudflare than with a random shady VPN or nothing.

Re: WARP is here

#80
post #55

Can someone explain the difference between warp and warp+? I’ve read the blog and the App Store description, both of which completely fail to identify the difference.

Hopefully I can! WARP uses a protocol called WireGuard to secure your Internet traffic. Your encrypted traffic flows over that protocol to the closest Cloudflare data center before it is released onto the public Internet. WARP+ takes that one step further. Rather than releasing your traffic directly onto the Internet, we use all the data we have from our Argo product [1] to route your traffic to _another_ Cloudflare…

Why should a user pay $4.99/month for Warp+ when they can pay less than that for a traditional VPN that masks their IP address? Does the performance benefit make up for the relatively weaker privacy?
Post reply on HN